Live data from Hacker News

Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

cnbc.com

21–30 of 145 posts

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#21
post #13

Earlier quoted context omitted.

Because if you did that, you'd have to alert the pilots when the AoA sensors disagree and MCAS has been disabled. And you can't do that without training them on what that means, notably how the plane will now fly differently with what you might call "relaxed stability" at high angles of attack. And Boeing really really wanted to avoid retraining of pilots because apparently they had a contract with SouthWest that wou…

Related question: how does regulatory approval of planes work, worldwide? I read a few times that the FAA had approved the new plane too quickly, but don't other regulators have their word?

Not only that, but apparently they also delegated most of the certification duties to Boeing itself.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#22

"Instead of relying on a single sensor indicating the angle of the plane’s nose, MCAS will rely on data from both of the plane’s sensors" Why wouldn't you design it that way from the beginning? This isn't Boeing's first plane.

Worse. Why don't they do it with three sensors and a voting system? By using two sensors, when they disagree, MCAS will have to be disabled. It seems the plane is unstable without MCAS, due to the forward positioning of the engines, requiring specific training and abilities from pilots.

No, it is not unstable without MCAS. MCAS is only designed to change the trim if the airplane is hand flown in flaps-retracted, low-speed, nose-up flight. This is something almost everyone is missing: A normal flight should not encounter this.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#23
post #11

Earlier quoted context omitted.

Maybe time was an issue? Saw in an earlier post that the issue had to be mitigated within 40 seconds of it occurring.

40 seconds is an eternity to accomplish the memory items on runaway stab trim non-normal checklist. It’s literally “control column - hold firmly” (already a given, since MCAS only affects manual flight and the increased back pressure required is the cue that something is amiss), “autopilot and autothrottle - disengage” (click-click, click-click), (if runaway continues) “stab trim cutout switches - cutout (both)”, (if…

Main stream media made it sound like 40 seconds is way too short of a time to troubleshoot the issue. But now that you state it that way, I gotta agree with you it's not Only Boeings fault. Sure they are big significant part of the issue. But not the only part.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#24
post #22

Earlier quoted context omitted.

Worse. Why don't they do it with three sensors and a voting system? By using two sensors, when they disagree, MCAS will have to be disabled. It seems the plane is unstable without MCAS, due to the forward positioning of the engines, requiring specific training and abilities from pilots.

No, it is not unstable without MCAS. MCAS is only designed to change the trim if the airplane is hand flown in flaps-retracted, low-speed, nose-up flight. This is something almost everyone is missing: A normal flight should not encounter this.

The way you describe it the faulty sensor would have not caused two crashes. If the code would check all these preconditions it would still ignore the AoA sensor.

It’s obvious that the code was executed during the regular flight conditions which means it has to be applied even then.

The motors simply push the plane nose up too much compared to the previous models, threating the plane to enter the stall. Once in the stall the plane is just not controllable. MCAS was there to hide that.

And now that the problem is known to the world either will Boeing provide the proper solution, no matter the cost, or there will be a third crash and that will be too much. Boring still tries to present all that as “business as usual.” It’s wrong.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#25
post #11

Earlier quoted context omitted.

Maybe time was an issue? Saw in an earlier post that the issue had to be mitigated within 40 seconds of it occurring.

40 seconds is an eternity to accomplish the memory items on runaway stab trim non-normal checklist. It’s literally “control column - hold firmly” (already a given, since MCAS only affects manual flight and the increased back pressure required is the cue that something is amiss), “autopilot and autothrottle - disengage” (click-click, click-click), (if runaway continues) “stab trim cutout switches - cutout (both)”, (if…

Going from previous discussion, apparently it would be hard for pilots to recognise it as trim runaway. The last description mentions: stall warning going off, column shake, incorrect airspeed (on one side, due to the faulty sensor), trim wheel doesn’t move, plus the fact MCAS operates in 10s intervals.

Has the information disclosed to pilots after the LyonAir incident been made public?

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#26

"Instead of relying on a single sensor indicating the angle of the plane’s nose, MCAS will rely on data from both of the plane’s sensors" Why wouldn't you design it that way from the beginning? This isn't Boeing's first plane.

Because if you did that, you'd have to alert the pilots when the AoA sensors disagree and MCAS has been disabled. And you can't do that without training them on what that means, notably how the plane will now fly differently with what you might call "relaxed stability" at high angles of attack. And Boeing really really wanted to avoid retraining of pilots because apparently they had a contract with SouthWest that wou…

It's worth noting that there are other more engineering reasons it could be tricky to use both. An aircraft in a side slip will show different reading on the left and right sensors. Also, there are failures which are likely to impact both at much the same time, icing being a big one.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#27
post #11

Earlier quoted context omitted.

Maybe time was an issue? Saw in an earlier post that the issue had to be mitigated within 40 seconds of it occurring.

40 seconds is an eternity to accomplish the memory items on runaway stab trim non-normal checklist. It’s literally “control column - hold firmly” (already a given, since MCAS only affects manual flight and the increased back pressure required is the cue that something is amiss), “autopilot and autothrottle - disengage” (click-click, click-click), (if runaway continues) “stab trim cutout switches - cutout (both)”, (if…

The layperson in me wants to know why things like trim don't have a meter/display that shows the actual setting. Seeing +6/-6 seems like it might trigger recognition of runaway adjustment.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#28
post #22

Earlier quoted context omitted.

Worse. Why don't they do it with three sensors and a voting system? By using two sensors, when they disagree, MCAS will have to be disabled. It seems the plane is unstable without MCAS, due to the forward positioning of the engines, requiring specific training and abilities from pilots.

No, it is not unstable without MCAS. MCAS is only designed to change the trim if the airplane is hand flown in flaps-retracted, low-speed, nose-up flight. This is something almost everyone is missing: A normal flight should not encounter this.

>> This is something almost everyone is missing: A normal flight should not encounter this.

Nobody said there was anything abnormal about the two flights that crashed. It really doesn't matter since the root problem is the plane doing things without telling anyone and then doing it wrongly. Without MCAS these accidents would not have happened.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#29
post #11

That's not very surprising to anyone who has been following along. The more interesting question is why they failed to identify the trim runaway condition, or if they did indeed identify it, why the procedure failed to correct it? This is significantly different to the Lion air incident where you can easily give the pilots the benefit of the doubt because the failure mode hadn't been previously identified. The detail…

Maybe time was an issue? Saw in an earlier post that the issue had to be mitigated within 40 seconds of it occurring.

I am not talking about these specific pilots about which I know nothing. But not every single commercial pilot is passionate about his job. For some it is just a day job and until they are asked to do a particular training, may not even be aware that MCAS even exists.

Think professional developers (granted the bar is infinitely lower). You would assume no one would introduce a SQL injection vulnerability in new code given all we know and all that happened. Well...

Also some commercial pilot on HN provided another element of answer. When you are in an emergency situation, you don't have the time to sit back and think, you revert to experience, muscle memory and training. Even if it may have crossed these guys mind that it was the same problem than Lion air, they may not necessarily know the procedure to fix it while trying to keep the plane from crashing at the same time.

Just speculating.

Re: Preliminary conclusion MCAS misfired in Ethiopian's 737 max crash

#30

"Instead of relying on a single sensor indicating the angle of the plane’s nose, MCAS will rely on data from both of the plane’s sensors" Why wouldn't you design it that way from the beginning? This isn't Boeing's first plane.

It brings up the question of what it means for the two sensors to disagree. How much do they have to disagree? For how long? How many times? The atmosphere is full of weird effects that can transiently make the two sensors be different. How much and for how long do you get to disable the MCAS system until you can't claim it as a protection? If you can disable it whenever things get strange then why have it at all?

There is a tendency to fixate on the bug that caused a crash to the extent that you introduce new more new bugs than you had before.

Post reply on HN